Risk warning method, device, equipment and computer storage medium

By extracting and fusion of the attribute information and financial data of the target object, using deep neural networks for risk assessment, and automatically determining the type of crime-related and suspicious characteristics of the target, the problems of low trial efficiency and poor accuracy in the existing technology are solved, and efficient and accurate risk warnings are achieved.

CN114462742BActive Publication Date: 2025-09-02TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202011247241.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-11-10
Publication Date
2025-09-02
Estimated Expiration
2040-11-10

AI Technical Summary

Technical Problem

The anti-money laundering trial system of existing financial institutions cannot actively prompt customers for risk types, resulting in low trial efficiency, poor accuracy, and high requirements for manual experience.

Method used

By obtaining the attribute information and financial data of the target object, feature extraction and fusion are performed, risk assessment is used using deep neural networks, the target crime-related types and suspicious characteristics are automatically determined, and the results are prompted to the reviewer.

Benefits of technology

Automatic risk assessment is achieved, review efficiency and accuracy are improved, and the requirements for the experience of auditors are reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114462742B_ABST
    Figure CN114462742B_ABST
Patent Text Reader

Abstract

The embodiments of the present application provide a risk warning method, apparatus, device and computer storage medium, which relate to the field of artificial intelligence technology. The method includes: extracting features from the attribute information and financial data in the characteristic information of the target object to obtain a fused feature vector corresponding to the attribute information and the financial data; conducting a risk assessment on the fused feature vector to obtain an evaluation label vector for the target object; determining the target crime type of the target object and at least one suspicious feature corresponding to the target crime type based on the evaluation label vector; sending the target crime type and at least one of the suspicious features as risk warning information to the client to implement a risk warning for the target object. Through the embodiments of the present application, it is possible to help auditors quickly and accurately locate possible risks of customers, greatly improving the efficiency and accuracy of the review, while also reducing the requirements for auditor experience.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of Internet technology, and are related to, but not limited to, a risk warning method, apparatus, device, and computer storage medium. Background Art

[0002] Currently, financial institutions' anti-money laundering review systems generally only provide basic customer attributes and transaction summaries. They don't proactively identify customer risk types or provide personalized risk profiles that match those risk types. Essentially, risk reporting relies solely on manual analysis and experience. This manual review approach clearly suffers from low efficiency, poor accuracy, and a high demand for human experience. Summary of the Invention

[0003] The present invention provides a risk warning method, apparatus, device, and computer storage medium, relating to the field of artificial intelligence technology. Based on the target object's attribute information and financial data, a risk assessment is performed on the target object to obtain the target crime type and at least one suspicious feature of the target object. The target crime type and suspicious feature are then presented to the auditor, enabling automatic risk assessment, thereby helping the auditor quickly and accurately identify the client's potential risks, significantly improving the efficiency and accuracy of the review process.

[0004] The technical solution of the embodiment of the present application is implemented as follows:

[0005] This embodiment of the present application provides a risk warning method, including:

[0006] Acquiring characteristic information of a target object, the characteristic information including at least attribute information of the target object and financial data corresponding to a financial business of the target object;

[0007] Performing feature extraction on the attribute information and the financial data to obtain a fused feature vector corresponding to the attribute information and the financial data;

[0008] Performing risk assessment on the fused feature vector to obtain an assessment label vector of the target object;

[0009] determining, based on the evaluation label vector, a target crime type of the target object and at least one suspicious feature corresponding to the target crime type;

[0010] At least one of the target crime type and the suspicious feature is sent to the client as risk warning information to provide a risk warning to the target object.

[0011] The present invention provides a risk warning device, including:

[0012] an acquisition module, configured to acquire characteristic information of a target object, wherein the characteristic information includes at least attribute information of the target object and financial data corresponding to the financial business of the target object;

[0013] a feature extraction module, configured to extract features from the attribute information and the financial data to obtain a fused feature vector corresponding to the attribute information and the financial data;

[0014] A risk assessment module, configured to perform risk assessment on the fused feature vector to obtain an assessment label vector for the target object;

[0015] a determination module, configured to determine, based on the evaluation label vector, a target crime type of the target object and at least one suspicious feature corresponding to the target crime type;

[0016] The sending module is used to send at least one of the target crime type and the suspicious feature as risk warning information to the client to implement risk warning for the target object.

[0017] An embodiment of the present application provides a computer program product or a computer program, which includes computer instructions, and the computer instructions are stored in a computer-readable storage medium; wherein a processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor is used to execute the computer instructions to implement the above-mentioned risk warning method.

[0018] The present invention provides a risk warning device, including:

[0019] The memory is used to store executable instructions; the processor is used to implement the above-mentioned risk warning method when executing the executable instructions stored in the memory.

[0020] An embodiment of the present application provides a computer-readable storage medium storing executable instructions for causing a processor to execute the executable instructions to implement the above-mentioned risk warning method.

[0021] The embodiments of the present application have the following beneficial effects: feature extraction is performed on the attribute information and financial data of the target object to obtain a fused feature vector, and risk assessment is performed on the target object based on the fused feature vector to obtain the target crime type and at least one suspicious feature of the target object, and the target crime type and suspicious feature are sent to the client as risk warning information to implement risk warning for the target object. In this way, automatic risk assessment can be implemented to accurately determine the target crime type and suspicious features of the target object, thereby helping auditors to quickly and accurately locate possible risks of customers, greatly improving the efficiency and accuracy of the review, and also reducing the requirements for auditor experience. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] Figure 1 This is an optional architectural diagram of the risk warning system provided in the embodiment of the present application;

[0023] Figure 2 This is a schematic diagram of the structure of the server provided in the embodiment of the present application;

[0024] Figure 3 This is an optional flowchart of the risk warning method provided in the embodiment of the present application;

[0025] Figure 4 This is an optional flowchart of the risk warning method provided in the embodiment of the present application;

[0026] Figure 5 This is an optional flowchart of the risk warning method provided in the embodiment of the present application;

[0027] Figure 6 This is an optional flowchart of the risk warning method provided in the embodiment of the present application;

[0028] Figure 7 This is an optional flowchart of the risk assessment model training method provided in the embodiment of the present application;

[0029] Figure 8 This is a diagram of the reporting interface for money laundering risk analysis in related technologies;

[0030] Figure 9 This is a diagram of the reporting interface for money laundering risk analysis in an embodiment of the present application;

[0031] Figure 10 This is an interface diagram for manually selecting the crime type provided in an embodiment of the present application;

[0032] Figure 11 This is a schematic diagram of the money laundering risk review process provided by an embodiment of the present application;

[0033] Figure 12 Schematic diagram of the structure of the deep neural network provided in the embodiment of the present application. DETAILED DESCRIPTION

[0034] In order to make the purpose, technical solutions and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. The described embodiments should not be regarded as limiting this application. All other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application.

[0035] In the following description, reference is made to "some embodiments," which describe a subset of all possible embodiments. However, it will be understood that "some embodiments" may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict. Unless otherwise defined, all technical and scientific terms used in the embodiments of this application have the same meaning as commonly understood by those skilled in the art to which the embodiments of this application pertain. The terms used in the embodiments of this application are for the purpose of describing the embodiments of this application only and are not intended to limit this application.

[0036] Before explaining the solutions of the embodiments of the present application, the nouns and special terms involved in the embodiments of the present application are first explained:

[0037] 1) Anti-money laundering: refers to financial institutions controlling money laundering risks within the system through certain processes and rules.

[0038] 2) Review: In the prevention and control of money laundering risks, suspicious customers who have passed the rule audit need to undergo manual investigation to confirm whether they are truly suspicious, so as to determine whether they need to be reported or not.

[0039] 3) Suspicious Characteristics: Certain attributes of a subject, such as "height", "age", "transaction amount in the last 7 days", etc. When certain characteristics or a combination of characteristics of a customer are different from those of a normal person, they are called suspicious characteristics.

[0040] 4) Crime type: After manual review and confirmation, the client's corresponding money laundering crime type will be determined. For example, money laundering crimes include gambling, drug trafficking, and pyramid schemes.

[0041] The embodiment of the present application proposes a risk warning method, which can help auditors quickly and accurately locate possible risks of customers through automatic intelligent machine recommendation of the crime type and suspicious characteristics of the target object, greatly improving the efficiency and accuracy of the trial, while also reducing the requirements for auditor experience.

[0042] The risk warning method provided by the embodiment of the present application first obtains characteristic information of the target object, wherein the characteristic information includes at least the attribute information of the target object and the financial data corresponding to the financial business of the target object; then, the attribute information and the financial data are subjected to feature extraction to obtain a fused feature vector corresponding to the attribute information and the financial data; the fused feature vector is subjected to risk assessment to obtain an evaluation label vector of the target object; based on the evaluation label vector, the target crime type of the target object and at least one suspicious feature corresponding to the target crime type are determined; finally, at least one of the target crime type and the suspicious feature is sent to the client as risk warning information to realize risk warning for the target object. In this way, an automated risk assessment can be realized to accurately determine the target crime type and suspicious features of the target object, thereby helping auditors to quickly and accurately locate possible risks of customers, greatly improving the efficiency and accuracy of the review, and also reducing the requirements for auditor experience.

[0043] The following describes an exemplary application of the risk warning device of the embodiment of the present application. In one implementation, the risk warning device provided by the embodiment of the present application can be implemented as a laptop computer, a tablet computer, a desktop computer, a mobile device (for example, a mobile phone, a portable music player, a personal digital assistant, a dedicated messaging device, a portable gaming device), an intelligent robot, or any other electronic device that can display the type of crime and suspicious characteristics of the client. In another implementation, the risk warning device provided by the embodiment of the present application can also be implemented as a server. The following describes an exemplary application of the risk warning device when it is implemented as a server. Risk warnings can be implemented through interaction between the server and the client of the terminal.

[0044] See also Figure 1 , Figure 1: This is an optional architectural diagram of the risk warning system 10 provided in the embodiment of the present application. In order to realize automatic risk warning for the target object, the risk warning system 10 provided in the embodiment of the present application includes a terminal 100, a network 200 and a server 300, wherein a review system application (for example, an application of an anti-money laundering review system) runs on the terminal 100, and the auditor can implement risk review of the target object on the client of the review system application. When conducting risk review, the server can adopt the method of the embodiment of the present application to automatically determine the target crime type and suspicious characteristics of the target object, and prompt the auditor to assist the auditor in conducting a rapid risk review. When providing a risk warning, server 300 obtains characteristic information of the target object sent by terminal 100 via network 200. This characteristic information includes at least the target object's attribute information and financial data corresponding to the target object's financial business. The server then extracts features from the attribute information and financial data to obtain a fused feature vector corresponding to the attribute information and financial data. The server then performs a risk assessment on the fused feature vector to obtain an assessment label vector for the target object. Based on the assessment label vector, the server determines the target crime type and at least one suspicious feature corresponding to the target crime type. Simultaneously, the server transmits at least one of the target crime type and the suspicious feature as risk warning information to the client on terminal 100 via network 200, thereby providing a risk warning to the target object. Upon receiving the risk warning information, terminal 100 may directly display the received risk warning information on current interface 100-1.

[0045] The risk warning method provided in the embodiments of the present application also relates to the field of artificial intelligence technology, and can be implemented at least through natural language processing and machine learning technologies in artificial intelligence technology. Among them, natural language processing (NLP) is an important direction in the fields of computer science and artificial intelligence. It studies various theories and methods that can achieve effective communication between humans and computers using natural language. Natural language processing is a science that integrates linguistics, computer science, and mathematics. Therefore, research in this field will involve natural language, that is, the language people use in daily life, so it is closely related to the study of linguistics. Natural language processing technology generally includes text processing, semantic understanding, machine translation, robot question answering, knowledge graph and other technologies. Machine learning (ML) is a multi-disciplinary interdisciplinary subject that involves multiple disciplines such as probability theory, statistics, approximation theory, convex analysis, and algorithmic complexity theory. It specializes in studying how computers simulate or implement human learning behavior to acquire new knowledge or skills and reorganize existing knowledge structures to continuously improve their own performance. Machine learning is the core of artificial intelligence and the fundamental way to make computers intelligent. Its applications are spread across all fields of artificial intelligence. Machine learning and deep learning generally include artificial neural networks, belief networks, reinforcement learning, transfer learning, inductive learning, and self-learning techniques. In the embodiments of the present application, machine learning techniques are used to respond to network structure search requests, automatically search for the target network structure, and train and optimize the controller and score model.

[0046] Figure 2 is a structural diagram of the server 300 provided in an embodiment of the present application, Figure 2 The server 300 shown includes: at least one processor 310, a memory 350, at least one network interface 320, and a user interface 330. The various components in the server 300 are coupled together via a bus system 340. It is understood that the bus system 340 is used to achieve connection and communication between these components. In addition to the data bus, the bus system 340 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, the bus system 340 is not described in detail. Figure 2 Various buses are labeled as bus system 340 .

[0047] The processor 310 can be an integrated circuit chip with signal processing capabilities, such as a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc., where the general-purpose processor can be a microprocessor or any conventional processor, etc.

[0048] The user interface 330 includes one or more output devices 331 that enable presentation of media content, including one or more speakers and / or one or more visual display screens. The user interface 330 also includes one or more input devices 332, including user interface components that facilitate user input, such as a keyboard, mouse, microphone, touch screen display, camera, other input buttons and controls.

[0049] The memory 350 may be removable, non-removable, or a combination thereof. Exemplary hardware devices include solid-state memory, hard disk drives, optical disk drives, and the like. The memory 350 may optionally include one or more storage devices physically located away from the processor 310. The memory 350 includes a volatile memory or a non-volatile memory, and may also include both volatile and non-volatile memories. The non-volatile memory may be a read-only memory (ROM), and the volatile memory may be a random access memory (RAM). The memory 350 described in the embodiments of the present application is intended to include any suitable type of memory. In some embodiments, the memory 350 is capable of storing data to support various operations, examples of which include programs, modules, and data structures, or subsets or supersets thereof, as exemplified below.

[0050] Operating system 351, including system programs for processing various basic system services and performing hardware-related tasks, such as the framework layer, core library layer, and driver layer, which are used to implement various basic services and process hardware-based tasks;

[0051] A network communication module 352 for reaching other computing devices via one or more (wired or wireless) network interfaces 320 , exemplary network interfaces 320 including Bluetooth, WiFi, and USB;

[0052] The input processing module 353 is configured to detect one or more user inputs or interactions from one of the one or more input devices 332 and to translate the detected inputs or interactions.

[0053] In some embodiments, the apparatus provided in the embodiments of the present application may be implemented in software. Figure 2A risk warning device 354 stored in memory 350 is shown. This risk warning device 354 may be a risk warning device in server 300 and may be software in the form of a program or plug-in. It includes the following software modules: an acquisition module 3541, a feature extraction module 3542, a risk assessment module 3543, a determination module 3544, and a sending module 3545. These modules are logical and can be arbitrarily combined or further separated according to the functions they implement. The functions of each module will be described below.

[0054] In other embodiments, the apparatus provided in the embodiments of the present application may be implemented in hardware. As an example, the apparatus provided in the embodiments of the present application may be a processor in the form of a hardware decoding processor, which is programmed to execute the risk warning method provided in the embodiments of the present application. For example, the processor in the form of a hardware decoding processor may be one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), or other electronic components.

[0055] The following will describe the risk warning method provided by the embodiment of the present application in conjunction with the exemplary application and implementation of the server 300 provided by the embodiment of the present application. Figure 3 , Figure 3 This is an optional flow chart of the risk warning method provided in the embodiment of the present application, which will be combined with Figure 3 The steps shown are explained.

[0056] Step S301: Acquire characteristic information of a target object, where the characteristic information at least includes attribute information of the target object and financial data corresponding to the financial business of the target object.

[0057] Here, the characteristic information of the target object input through the terminal can be obtained, or the basic information input by the target object can be identified and analyzed to obtain the characteristic information, or the characteristic information corresponding to the target object can be obtained from the database. In the embodiment of the present application, the target user can be any person, any merchant, or any group.

[0058] The characteristic information includes at least the target object's attribute information and financial data corresponding to the target object's financial business. The target object's attribute information may include the target object's identity information, for example, the target object's social attribute information (such as position, nature of work, work unit, etc.), natural attribute information (such as gender, age, etc.), account attribute information (such as bank card number, online banking, Alipay account, etc.), and other information that can reflect the target object's attribute information and may affect whether the target object is involved in a crime. This other information may include, for example, logistics-related information, equipment information, complaint information, etc. The financial data corresponding to the target object's financial business may include, but is not limited to: transaction summary data, transaction amount, account balance, bill change information, etc.

[0059] Step S302 : extracting features from the attribute information and the financial data to obtain a fused feature vector corresponding to the attribute information and the financial data.

[0060] In embodiments of the present application, a pre-trained risk assessment model can be used to implement risk assessment to ultimately determine the target's crime type. The risk assessment model can be any deep neural network, comprising at least an input layer, a feature extraction layer, a risk assessment layer, and an output layer. The feature extraction layer is used to extract features from the input attribute information and financial data, generating a fused feature vector corresponding to the attribute information and financial data. This fused feature vector is then fed into the risk assessment layer for further vector transformation processing to obtain the final output vector.

[0061] Step S303: perform risk assessment on the fused feature vector to obtain an assessment label vector of the target object.

[0062] The evaluation label vector is a label vector used to determine the target setting type of the target object. The evaluation label vector has at least two dimensions, each dimension corresponding to a crime type.

[0063] Step S304 : determining the target crime type of the target object and at least one suspicious feature corresponding to the target crime type according to the evaluation label vector.

[0064] The risk assessment here refers to determining whether the target object is involved in a crime, and if so, the type of crime the target object is involved in, based on the acquired attribute information and financial data of the target object. After determining the type of crime the target object is involved in, suspicious features related to the type of crime are selected from the attribute information and financial data.

[0065] In the embodiment of the present application, the crime type includes, but is not limited to, any of the following: fraud, gambling, illegal business operations, usury, pyramid schemes, etc. In the embodiment of the present application, suspicious features of the target user are determined based on the determined crime type, where the suspicious features are features in the attribute information and financial data. That is, after determining the target crime type, at least one piece of information or data is selected from the multiple pieces of attribute information and the multiple pieces of financial data as a suspicious feature.

[0066] Step S305: sending at least one of the target crime type and suspicious feature as risk warning information to the client to provide risk warning to the target object.

[0067] Here, after the target crime type and suspicious characteristics are determined, the target crime type and suspicious characteristics are displayed to the reviewer as risk warning information, so that when the reviewer reviews the target object, he or she can use the displayed target crime type and suspicious characteristics as a basis and reference to conduct a more accurate review of the target object.

[0068] In an embodiment of the present application, only the target crime type of the target object can be displayed on the client interface, only the suspicious features of the target object can be displayed on the client interface, or both the target crime type and the suspicious features can be displayed at the same time.

[0069] The risk assessment method provided in the embodiment of the present application performs feature extraction on the attribute information and financial data of the target object to obtain a fused feature vector, and performs risk assessment on the target object based on the fused feature vector to obtain the target crime type and at least one suspicious feature of the target object, and sends the target crime type and suspicious feature as risk warning information to the client to implement risk warning for the target object. In this way, automatic risk assessment can be implemented to accurately determine the target crime type and suspicious features of the target object, thereby helping auditors to quickly and accurately locate possible risks of customers, greatly improving the efficiency and accuracy of the review, and also reducing the requirements for auditor experience.

[0070] The following describes the application scenarios of the risk assessment method of the embodiment of the present application in conjunction with the risk assessment system of the embodiment of the present application:

[0071] In one application scenario, the risk assessment system includes a terminal and a server. An audit system application runs on the terminal, and auditors can use the audit system application to perform audits and risk assessments. Figure 4 This is an optional flow chart of the risk warning method provided in the embodiment of the present application, such as Figure 4 As shown, the method includes the following steps:

[0072] Step S401: The terminal obtains characteristic information of a target object, where the characteristic information at least includes attribute information of the target object and financial data corresponding to the financial business of the target object.

[0073] Here, the target object is the customer for whom the auditor needs to conduct a risk assessment. This can be done by identifying the information uploaded by the customer to obtain the customer's characteristic information, or by summarizing the customer's information stored in the system within a historical time period to obtain the customer's characteristic information.

[0074] Step S402: The terminal sends the characteristic information of the target object to the server.

[0075] In step S403, the server inputs the attribute information and financial data into a pre-trained risk assessment model, performs feature extraction on the attribute information and financial data through the feature extraction layer of the risk assessment model, and obtains a fusion feature vector corresponding to the attribute information and financial data.

[0076] In the embodiments of the present application, a pre-trained risk assessment model can be used to implement risk assessment and ultimately determine the target's crime type. The risk assessment model can be any deep neural network and has at least an input layer, a feature extraction layer, a risk assessment layer, and an output layer. The feature extraction layer is used to extract features from the input attribute information and financial data to obtain a fused feature vector corresponding to the attribute information and financial data.

[0077] In step S404, the server performs risk assessment on the fused feature vector through the risk assessment layer of the risk assessment model to obtain an assessment label vector of the target object.

[0078] Here, the evaluation label vector is a label vector used to determine the target setting type of the target object. The evaluation label vector has at least two dimensions, each dimension corresponding to a crime type.

[0079] Step S405: The server determines the target crime type of the target object according to the evaluation label vector.

[0080] Here, the target crime type of the target object can be determined based on the value of the component of each dimension in the evaluation label vector. For example, the crime type corresponding to the dimension with the maximum value in the evaluation label vector can be determined as the target crime type.

[0081] In step S406, the server determines at least one attribute information and at least one financial data in the feature information as suspicious features based on the target crime type.

[0082] Here, after determining the target crime type, at least one feature information in the feature information that is strongly correlated or most correlated with the target crime type is determined as a suspicious feature, wherein the suspicious feature includes not only attribute information but also financial data.

[0083] In step S407, the server sends at least one of the target crime type and suspicious feature as risk warning information to the client on the terminal to provide risk warning to the target object.

[0084] In step S408, the reviewer uses the risk warning information as auxiliary information to review the risk of the target object.

[0085] In another application scenario, the risk assessment system includes a terminal and a server. A risk assessment application runs on the terminal. Users can use the risk assessment application to query the financial system's risk assessment of their own risks. In this case, the server can be the client server of the risk assessment application. The user enters his or her own characteristic information on the terminal. The characteristic information includes at least the user's attribute information and financial data corresponding to the user's financial business.

[0086] After obtaining the user's characteristic information, the terminal sends it to the server, which then uses a pre-trained risk assessment model to perform a risk assessment on the user. During implementation, the server inputs the attribute information and financial data from the user's characteristic information into the risk assessment model. The feature extraction layer of the risk assessment model extracts features from the attribute information and financial data, generating a fused feature vector corresponding to the attribute information and financial data. The risk assessment layer of the risk assessment model then performs a risk assessment on the fused feature vector to generate the user's assessment label vector. The user's target crime type is then determined based on the assessment label vector. Based on the target crime type, at least one attribute information and at least one financial data item in the characteristic information is identified as a suspicious feature. After the server obtains the user's target crime type and financial data, it sends these as risk warning information to the client on the terminal, enabling the user to query the risk assessment results.

[0087] In another application scenario, the risk assessment system includes a terminal and a server, and a risk assessment application runs on the terminal. The risk assessment application can be an application of the government system that performs risk assessment on merchants or individuals. When government personnel of the government system handle related business for merchants or individuals, they need to first conduct risk assessment and query on the merchant or individual. Therefore, the risk assessment of the financial system on the merchant or individual can be queried through the risk assessment application. At this time, the server can be the client server of the risk assessment application, and the government personnel enter the characteristic information of the merchant or individual on the terminal. The characteristic information includes at least the user's attribute information and the financial data corresponding to the user's financial business.

[0088] After obtaining the characteristic information of the merchant or individual, the terminal sends this characteristic information to the server, which then uses a pre-trained risk assessment model to perform a risk assessment on the merchant or individual. During implementation, the server inputs the attribute information and financial data from the merchant or individual's characteristic information into the risk assessment model. The feature extraction layer of the risk assessment model extracts features from the attribute information and financial data to obtain a fused feature vector corresponding to the attribute information and financial data. The risk assessment layer of the risk assessment model then performs a risk assessment on the fused feature vector to obtain an assessment label vector for the merchant or individual. The target crime type of the merchant or individual is then determined based on the assessment label vector. Based on the target crime type, at least one attribute information and at least one financial data item in the characteristic information is identified as a suspicious feature. After the server obtains the target crime type and financial data of the merchant or individual, it sends these as risk warning information to the client on the terminal, enabling government officials to query the risk assessment results for the merchant or individual.

[0089] Below Figure 4 As an example of the application scenario, the risk warning method of the embodiment of the present application will be described. Figure 4 , Figure 5 This is an optional flow chart of the risk warning method provided in the embodiment of the present application, such as Figure 5 As shown, in some embodiments, step S403 can be implemented by the following steps:

[0090] Step S501 : performing binning and discretization processing or equal-frequency binning and discretization processing on the attribute information and the financial data, respectively, to obtain a discrete vector of the attribute information and a discrete vector of the financial data.

[0091] Here, binning is a top-down splitting technique based on a specified number of bins. Binning can be used as a discretization method for data reduction and concept hierarchy generation. For example, by using equal-width or equal-frequency bins and then replacing each value in the bin with the bin mean or median, the attribute value can be discretized, just like smoothing with the bin mean or bin median. In the embodiments of the present application, attribute information and financial data are processed through binning discretization or equal-frequency binning discretization to obtain discrete vectors of attribute information and discrete vectors of financial data.

[0092] Step S502 : Concatenate the discrete vector of the attribute information and the discrete vector of the financial data to form a concatenated vector.

[0093] Here, multiple low-dimensional discrete vectors of attribute information and multiple low-dimensional discrete vectors of financial data can be concatenated to form a concatenated vector with a higher dimension, where the dimension of the concatenated vector is equal to the sum of the dimensions of the discrete vectors of attribute information and the discrete vectors of financial data.

[0094] Step S503: determining the splicing vector as a fusion feature vector corresponding to the attribute information and the financial data.

[0095] Please continue to refer to Figure 5 In some embodiments, step S405 may be implemented by the following steps:

[0096] Step S504 : determining the crime type corresponding to the dimension of each component of the evaluation label vector.

[0097] Step S505 : Determine the dimension where the maximum component in the evaluation label vector resides as the target dimension.

[0098] Step S506: Determine the crime type corresponding to the target dimension as the target crime type of the target object.

[0099] based on Figure 4 , Figure 6 This is an optional flow chart of the risk warning method provided in the embodiment of the present application, such as Figure 6 As shown, in some embodiments, step S406 can be implemented in any of the following ways:

[0100] Step S601: Determine the influence degree between each attribute information and each financial data and the target crime type.

[0101] Here, the preset historical trial library stores: at least one crime type, at least one feature information corresponding to each crime type, and an IV value between each feature information and the crime type.

[0102] Step S601 can be implemented by the following steps:

[0103] Step S6011: query the historical trial database for the information value (IV) between each attribute information and each financial data and the target crime type.

[0104] During the historical review process, we also calculate the IV value between each attribute information and the crime type, and the IV value between each financial data item and the crime type, and store these calculated IV values ​​in the historical review database. This allows us to directly query the historical review database for the IV value of each attribute information item and each financial data item corresponding to the target crime type during subsequent predictions, once the target crime type has been determined.

[0105] Step S6012: The IV value between each attribute information and each financial data and the target crime type is determined as the influence degree value between the corresponding attribute information and the corresponding financial data and the target crime type.

[0106] Here, the higher the IV value, the higher the influence value between the corresponding attribute information or the corresponding financial data and the target crime type, indicating that the correlation between the attribute information or the financial data and the target crime type is higher, and the target crime type can be more easily derived through the attribute information or the financial data.

[0107] In some embodiments, in method 1, the following steps are further included:

[0108] Step S602 : sorting the attribute information and financial data in descending order of influence values ​​to form an information sequence including the attribute information and financial data.

[0109] It should be noted that in the embodiment of the present application, all attribute information and financial data corresponding to the feature information are sorted, and the formed information sequence includes not only attribute information but also financial data.

[0110] Step S603: Select a preset amount of attribute information and financial data in the information sequence.

[0111] Here, according to the arrangement order of the attribute information and the financial data in the information sequence, the first N information in the information sequence is selected. The N information may include not only the attribute information but also the financial data.

[0112] Step S604: Determine the selected attribute information and financial data as suspicious features.

[0113] In some embodiments, in the second method, the following steps are further included:

[0114] Step S605: Attribute information and financial data with an impact value greater than a preset threshold are determined as suspicious features. The preset threshold may be a pre-set value. When the impact value is greater than the preset threshold, it indicates that the attribute information and financial data are highly correlated with the target crime type, or that the attribute information and financial data are highly important to the target crime type. Therefore, attribute information and financial data with an impact value greater than the preset threshold can be determined as suspicious features corresponding to the target crime type.

[0115] The present invention provides a method for training a risk assessment model. Figure 7 This is an optional flow chart of the training method of the risk assessment model provided in the embodiment of the present application, such as Figure 7 As shown, the training method includes the following steps:

[0116] Step S701: input sample data of the sample object into the risk assessment model.

[0117] In an embodiment of the present application, the sample database stores sample data of at least one sample object. The sample data is data that has been risk assessed and reviewed in the historical risk assessment process. The sample data corresponds to a preset label, which is used to indicate the type of crime involved in the sample object.

[0118] In some embodiments, the reviewer will continuously update the sample data in the sample database and the preset labels corresponding to the sample data during the review process. The preset label can be a label manually set by the reviewer after review, and the label is the real label of the sample object.

[0119] In an embodiment of the present application, after determining the target crime type of the target object and at least one suspicious feature corresponding to the target crime type, the review operation of the reviewer is obtained, wherein the review operation includes an evaluation operation for the target crime type and the suspicious feature. The evaluation operation here refers to the reviewer evaluating the accuracy of the target crime type and the suspicious feature determined by the risk assessment model on the terminal. For example, an evaluation operation button may be provided on the terminal, and the evaluation operation button may include at least two options: accurate evaluation and inaccurate evaluation. When the reviewer selects the accurate evaluation option, the system uses the target crime type determined by the risk assessment model as the true label of the target object and stores it in the sample database together with the suspicious feature; when the reviewer selects the inaccurate evaluation option, an editable modification box or modification option pops up, and the reviewer can manually modify the risk assessment result. After the reviewer completes the modification, the modified target crime type is used as the true label of the target object and stored in the sample database together with the modified suspicious feature.

[0120] In some embodiments, after the risk assessment model determines the target crime type and suspicious characteristics of the target object, it also outputs the predicted accuracy of the target crime type and suspicious characteristics. At this time, if the predicted accuracy of the target crime type and suspicious characteristics is greater than the accuracy threshold, the target object's characteristic information is updated as sample data to the sample database, and the target crime type is determined as the preset label corresponding to the sample data. The method of the embodiment of the present application can realize automatic evaluation of the accuracy of the risk assessment model's prediction results, thereby improving the efficiency of sample data updating.

[0121] In other embodiments, after the risk assessment model determines the target crime type and suspicious features of the target object, the auditor can manually select or input the predicted accuracy of the target crime type and suspicious features, that is, obtain the auditor's audit operation, wherein the audit operation includes an evaluation operation for the target crime type and suspicious features, and the evaluation operation here is used to indicate the predicted accuracy of the target crime type and suspicious features. If the predicted accuracy input or manually selected by the auditor's evaluation operation is greater than the accuracy threshold, the characteristic information of the target object is updated as sample data to the sample database, and the target crime type is determined as the preset label corresponding to the sample data. The method of the embodiment of the present application can obtain an accurate evaluation of the risk assessment results through the auditor's evaluation operation on the risk assessment results, thereby improving the accuracy of the sample data update, and then when the risk assessment model is subsequently trained, more accurate sample data can be used for training, and a risk assessment model that can accurately perform risk assessment is obtained.

[0122] Step S702: extract features from the sample data through the feature extraction layer of the risk assessment model to obtain a sample feature vector.

[0123] Step S703 : performing risk assessment on the sample feature vector through the risk assessment layer of the risk assessment model to obtain a sample assessment label vector of the sample object.

[0124] Step S704: input the sample evaluation label vector into the preset loss model to obtain the loss result.

[0125] The preset loss model includes a loss function, and the loss result can be calculated through the loss function.

[0126] In some embodiments, step S704 may be implemented by the following steps:

[0127] Step S7041: Obtain the preset labels corresponding to the sample data. Step S7042: Encode the preset labels using the one-hot encoding rule to obtain an encoded label vector. Step S7043: Calculate the distance between the sample evaluation label vector and the encoded label vector using the loss function in the preset loss model. Step S7044: Determine the loss result based on the distance.

[0128] Here, the preset label is a pre-set true label. The loss function calculates the distance between the sample evaluation label vector and the encoded label vector. When the distance between the sample evaluation label vector and the encoded label vector is larger, it indicates that the risk assessment model's prediction result is inaccurate, and the risk assessment model needs to be further optimized and the parameters in the risk assessment model need to be updated and corrected. When the distance between the sample evaluation label vector and the encoded label vector is smaller, it indicates that the risk assessment model's prediction result is more accurate, and further optimization of the risk assessment model is not required.

[0129] Step S705: Based on the loss result, the parameters in the risk assessment model are updated using the stochastic gradient descent method until the sample evaluation label vector output by the updated risk assessment model meets the preset conditions, and then the training of the risk assessment model is stopped.

[0130] In the embodiment of the present application, the preset conditions include but are not limited to any one of the following: the trained risk assessment model has converged, the number of training times has reached the maximum allowed number of iterations, the training time has reached the maximum model training time, etc.

[0131] The risk assessment model training method provided in the embodiments of the present application inputs sample data of a sample object into the risk assessment model, performs feature extraction and risk assessment on the sample data in sequence through the feature extraction layer and the risk assessment layer, and then inputs the sample assessment label vector into a preset loss model to obtain a loss result. In this way, the parameters in the feature extraction layer and the risk assessment layer can be modified based on the loss result. The resulting risk assessment model can accurately determine the assessment label vector of the target object, thereby accurately performing risk assessment on the target object and improving the efficiency and accuracy of risk review.

[0132] The following describes an exemplary application of the embodiments of the present application in a practical application scenario.

[0133] The embodiments of the present application provide a risk warning method that can help auditors quickly and accurately locate possible risks of customers, greatly improving the efficiency and accuracy of review, while also reducing the requirements for auditor experience.

[0134] The products in the related technologies generally do not have any prompts during the money laundering risk analysis phase. Auditors can only record relevant risk information in a notebook or Excel account, and then gradually write the report in the blank space on the report page, select risk characteristics and other information, such as Figure 8 As shown, it is a diagram of the reporting interface of money laundering risk analysis in related technologies. In the reporting interface, the auditor needs to manually select multiple options such as audit results, suspicious characteristics, transaction characteristics, processing status, effective stratification and processing basis. The audit process is cumbersome and the audit efficiency is low. At the same time, the auditor needs to have certain audit experience.

[0135] This embodiment of the present application provides a risk warning method that can assist auditors in conducting money laundering risk assessments. After modification of this embodiment of the present application, during the analysis phase of the development and assessment task, the client's money laundering risk type and related risk characteristics are directly indicated, thereby greatly reducing the difficulty and complexity of the assessment and improving the efficiency of the assessment. Figure 9 This is a diagram of the reporting interface for money laundering risk analysis in the embodiment of the present application. When the auditor reports the risk, the system will automatically prompt the customer's crime type 901 and suspicious characteristics 902. Based on the prompted crime type and suspicious characteristics, the auditor can quickly characterize and report the customer's risk.

[0136] In some embodiments, if the user finds through analysis that the recommended crime type is inaccurate, he or she may manually select the corresponding crime type. The following suspicious features will also change accordingly based on the crime type and the customer's risk attributes to meet the regulatory requirements reported by the customer. Figure 10 This is an interface diagram for manually selecting the crime type provided in the embodiment of the present application, such as Figure 10 As shown, in the crime type option, a drop-down option 1001 can be provided, and the reviewer can click the drop-down option 1001 to select the accurate crime type to correct the prediction result.

[0137] Figure 11 This is a schematic diagram of the money laundering risk review process provided by the embodiment of the present application, such as Figure 11 As shown, the review process includes the following three steps:

[0138] Step 1 involves data collection. The user's social attributes, natural attributes, and account attributes required by the model algorithm, as well as user transaction summary data, logistics-related data, equipment data, and complaint data, are collected and aggregated to obtain data source 1101. This data source 1101 is stored in a feature database for future use. In this embodiment, data source 1101 includes at least TDW data, relational database management system (MySQL) data, and various system data.

[0139] Step 2 is model calculation. Using data and algorithms, a recommendation value is calculated 1102. Based on the characteristic information of clients corresponding to historical trial tasks, as well as the crime types and suspicious characteristics selected after manual trials, the model is calculated for the new task data to recommend the most likely crime types and the most relevant suspicious characteristics. The recommended crime types and characteristics are then pushed to the trial system 1103 for backup.

[0140] Step three is the review system display. When the reviewer opens the review task, the system automatically displays the crime type and suspicious characteristics recommended by the model, automatically providing a crime type prompt 1104 and a risk characteristic prompt 1105, helping the reviewer quickly determine the customer's risk type and suspicious characteristics and write the corresponding report.

[0141] The following is an introduction to the automatic learning algorithm based on historical trial conclusions:

[0142] Here we use a deep neural network to solve the problem of predicting multi-class crime types. It includes the following steps:

[0143] The first step is data preprocessing:

[0144] This involves collecting black and white sample labels, collecting features, and preprocessing the features. Reviewers will continuously update the label library (including the client's crime type and suspicious behavior) and the feature library (selecting which client features are valuable for determining the final crime type). Once the client's feature library is in place, each feature needs to be processed, specifically binned. A single feature can be discretized into multiple features, each a two-dimensional variable representing either 0 or 1. For example, a client's inflow amount over the past 30 days can be divided into five data segments: less than or equal to 10,000 yuan, greater than 100,000 yuan and less than or equal to 1 million yuan, greater than 1 million yuan and less than or equal to 10 million yuan, and greater than 10 million yuan. Each client is assigned to one of these data segments. This means that the client's value in that segment is 1, while the values ​​in other segments are 0. For example, if a client's inflow amount is 500,000 yuan, the corresponding value for this feature is (0, 0, 1, 0, 0). The above binning method can also be implemented using the equal-frequency binning method. Equal-frequency binning sorts the feature data and selects N user-specified quantiles as bin boundaries in a quantile manner. If adjacent quantiles are the same, the two bins are merged. Therefore, the binning result may have fewer bins than the number specified by the user. For example, the four quantiles (20%, 40%, 60%, 80%) corresponding to the customer's number of transactions are 10, 20, 50, and 100 transactions, respectively. Then, the data is divided into five segments based on these four points. The significance of feature binning is to reduce the interference of outliers, to group customers with similar features together, and to ensure that each segment feature has statistical significance, thereby reducing overfitting of the model.

[0145] Crime labels (labels representing crime types or related crimes) are vectorized using one-hot encoding. For example, consider three types of labels (underground banking, pyramid scheme, and not suspicious). Each customer corresponds to only one of these, so the corresponding type is assigned a value of 1, and the others are assigned a value of 0. This creates a one-hot vector. For example, if a customer is labeled as an underground banking customer, their crime label is (1, 0, 0). If they are not suspicious, their crime label is (0, 0, 1).

[0146] The second step is to train the multi-classification model:

[0147] With the above feature processing and labeling steps in place, we will now train a deep neural network (DNN) model. The model's training set consists of data that has been labeled by auditors. Each record represents a customer's information and includes the pre-processed features and crime labels described in the previous step. The deep learning network can then be used to build a multi-classification prediction model.

[0148] Figure 12 It is a structural diagram of the deep neural network provided in the embodiment of the present application. The first layer of the deep neural network (i.e., the risk assessment model) is the feature input layer 121, the last layer is the output layer 122, and the middle layer 123 is a hidden layer for performing different transformations on the vector output by the input layer 121. The output vector of the output layer 122 represents the probability of each type. In the embodiment of the present application, a loss function based on cross entropy can be established by the forward propagation method, and then each weight value in the iterative deep neural network can be gradually updated by the stochastic gradient descent method. After multiple rounds of iterations, the optimal value is finally reached. This completes the model establishment.

[0149] The third step is to make predictions using the trained risk assessment model:

[0150] Here, with a trained risk assessment model, for any customer, as long as all the characteristic information of the customer is input, a label vector can be output, and then the dimension with the largest value in the label vector is taken as the category label of the customer to determine the target crime type of the customer.

[0151] The fourth step is to recommend important features based on feature analysis methods.

[0152] After predicting the crime type described above, we can recommend the features most relevant to that crime type. Specifically, we can identify one or more features most relevant to that crime type as suspicious features. This requires calculating and statistically analyzing the importance of each crime type and the corresponding features from the historical trial database. For example, we can calculate the IV value between each feature and the crime type to determine how well the feature distinguishes the crime type. After calculating the IV value, we sort the features by IV value, and select the top N features with the largest IV values ​​as the recommended features for display.

[0153] The method provided in the embodiment of the present application, after the crime type assessment, when the model completely hits the crime type and suspicious features, it can be reported after a simple manual review, and the review time can be reduced from 8 minutes / task to about 2 minutes / task, an efficiency improvement of 600%. If the crime type and suspicious features hit by the model deviate, the average review time is about 4 minutes / task, an efficiency improvement of 100%. In this way, for an operation team of 40 people, at a cost of 100,000 / person / year, it can generate more than 4 million in benefits a year.

[0154] It should be noted that after the risk assessment model calculates and recommends the crime type and suspicious features, it can be directly converted into a message statement and displayed in the message box to assist in writing the message, or only all suspicious features that meet the requirements can be displayed and inserted into the message by manual click. In terms of recommending and displaying suspicious features, the descriptions corresponding to all customer-related suspicious features can be displayed, or only suspicious features that are consistent with the selected crime type can be displayed, and suspicious features that are not related to the selected crime can be hidden. In addition, it is not necessary to recommend crime types and suspicious features at the same time. If necessary, only crime types or only suspicious features can be recommended. Moreover, the algorithm of the risk assessment model is not unique. Different algorithms can achieve this type of recommendation effect, and similar algorithms are within the scope of protection of this application.

[0155] The following continues to describe the exemplary structure of the risk prompting device 354 provided in the embodiment of the present application implemented as a software module. In some embodiments, such as Figure 2 As shown, the software module stored in the risk prompting device 354 of the memory 350 may be the risk prompting device in the server 300, including:

[0156] An acquisition module 3541 is configured to acquire characteristic information of a target object, wherein the characteristic information includes at least attribute information of the target object and financial data corresponding to the financial business of the target object;

[0157] A feature extraction module 3542 is configured to extract features from the attribute information and the financial data to obtain a fused feature vector corresponding to the attribute information and the financial data;

[0158] A risk assessment module 3543 is configured to perform risk assessment on the fused feature vector to obtain an assessment label vector for the target object;

[0159] a determination module 3544 configured to determine, based on the evaluation label vector, a target crime type of the target object and at least one suspicious feature corresponding to the target crime type;

[0160] The sending module 3545 is used to send at least one of the target crime type and the suspicious feature as risk warning information to the client to provide risk warning to the target object.

[0161] In some embodiments, the device further includes: a control module for using a pre-trained risk assessment model to determine the target crime type of the target object and at least one suspicious feature corresponding to the target crime type; correspondingly, the feature extraction module is further used to: perform feature extraction on the attribute information and the financial data through the feature extraction layer of the risk assessment model to obtain a fused feature vector corresponding to the attribute information and the financial data; the risk assessment module is further used to: perform risk assessment on the fused feature vector through the risk assessment layer of the risk assessment model to obtain an assessment label vector of the target object

[0162] In some embodiments, the risk assessment module is further used to: determine the target crime type of the target object based on the assessment label vector; and determine at least one attribute information and at least one financial data in the feature information as the suspicious feature based on the target crime type.

[0163] In some embodiments, the risk assessment module is further used to: perform binning and discretization processing or equal-frequency binning and discretization processing on the attribute information and the financial data respectively to obtain a discrete vector of the attribute information and a discrete vector of the financial data; splice the discrete vector of the attribute information and the discrete vector of the financial data to form a spliced ​​vector; and determine the spliced ​​vector as a fusion feature vector corresponding to the attribute information and the financial data.

[0164] In some embodiments, the risk assessment module is further used to: determine the crime type corresponding to the dimension where each component of the evaluation label vector is located; determine the dimension where the maximum component in the evaluation label vector is located as the target dimension; and determine the crime type corresponding to the target dimension as the target crime type of the target object.

[0165] In some embodiments, the risk assessment module is further used to: respectively determine the influence degree value between each of the attribute information and each of the financial data and the target crime type; sort the attribute information and the financial data in descending order of the influence degree value to form an information sequence containing the attribute information and the financial data; select a preset number of attribute information and financial data from the information sequence; and determine the selected attribute information and financial data as the suspicious features.

[0166] In some embodiments, the risk assessment module is further used to: respectively determine the influence degree value between each of the attribute information and each of the financial data and the target crime type; and determine the attribute information and financial data whose influence degree value is greater than a preset threshold as the suspicious feature.

[0167] In some embodiments, a preset historical trial library stores: at least one crime type, at least one characteristic information corresponding to each crime type, and an IV value between each characteristic information and the crime type; the risk assessment module is also used to: query the IV value between each attribute information and each financial data and the target crime type from the historical trial library; and determine the IV value between each attribute information and each financial data and the target crime type as the impact degree value between the corresponding attribute information and the corresponding financial data and the target crime type.

[0168] In some embodiments, the risk assessment model is trained through the following steps: inputting sample data of a sample object into the risk assessment model; performing feature extraction on the sample data through the feature extraction layer of the risk assessment model to obtain a sample feature vector; performing risk assessment on the sample feature vector through the risk assessment layer of the risk assessment model to obtain a sample evaluation label vector of the sample object; inputting the sample evaluation label vector into a preset loss model to obtain a loss result; and based on the loss result, using the stochastic gradient descent method to update the parameters in the risk assessment model until the sample evaluation label vector output by the updated risk assessment model meets a preset condition, and then stopping the training of the risk assessment model.

[0169] In some embodiments, the risk assessment model is trained through the following steps: obtaining the preset label corresponding to the sample data; encoding the preset label using the one-hot encoding rule to obtain the encoded label vector; using the loss function in the preset loss model to calculate the distance between the sample evaluation label vector and the encoded label vector; and determining the loss result based on the distance.

[0170] In some embodiments, the device further includes: an audit operation acquisition module for acquiring the audit operation of the auditor after determining the target crime type of the target object and at least one suspicious feature corresponding to the target crime type, wherein the audit operation includes an evaluation operation for the target crime type and the suspicious feature; an update module for updating the characteristic information of the target object as the sample data to the sample database when the evaluation operation indicates that the prediction accuracy of the target crime type and the suspicious feature is greater than an accuracy threshold, and determining the target crime type as the preset label corresponding to the sample data.

[0171] It should be noted that the description of the device embodiment of the present application is similar to the description of the method embodiment described above, and has similar beneficial effects as the method embodiment, so it will not be repeated. For technical details not disclosed in the device embodiment, please refer to the description of the method embodiment of the present application for understanding.

[0172] The present invention provides a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the method described above in the present invention.

[0173] The embodiment of the present application provides a storage medium storing executable instructions, wherein the executable instructions are stored. When the executable instructions are executed by a processor, the processor will execute the method provided by the embodiment of the present application, for example, Figure 3 The method shown.

[0174] In some embodiments, the storage medium can be a computer-readable storage medium, such as a ferroelectric random access memory (FRAM), a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM); it can also be various devices including one or any combination of the above memories.

[0175] In some embodiments, executable instructions may be in the form of a program, software, software module, script, or code, written in any form of programming language (including compiled or interpreted languages, or declarative or procedural languages), and may be deployed in any form, including as a stand-alone program or as a module, component, subroutine, or other unit suitable for use in a computing environment.

[0176] By way of example, executable instructions may, but need not necessarily, correspond to a file in a file system, may be stored as part of a file storing other programs or data, such as one or more scripts in a Hypertext Markup Language (HTML) document, in a single file dedicated to the program in question, or in multiple coordinating files (e.g., files storing one or more modules, subroutines, or code portions). By way of example, executable instructions may be deployed for execution on one computing device, or on multiple computing devices located at one site, or on multiple computing devices distributed across multiple sites and interconnected by a communication network.

[0177] The above description is merely an embodiment of the present application and is not intended to limit the scope of protection of the present application. Any modifications, equivalent replacements, and improvements made within the spirit and scope of the present application are included in the scope of protection of the present application.

Claims

1. A risk warning method, characterized in that: include: Acquiring characteristic information of a target object, the characteristic information including at least attribute information of the target object and financial data corresponding to a financial business of the target object; extracting features from the attribute information and the financial data through a feature extraction layer of a pre-trained risk assessment model to obtain a fused feature vector corresponding to the attribute information and the financial data; Performing risk assessment on the fused feature vector through the risk assessment layer of the risk assessment model to obtain an assessment label vector of the target object; determining, based on the evaluation label vector, a target crime type of the target object and at least one suspicious feature corresponding to the target crime type; At least one of the target crime type and the suspicious feature is sent to the client as risk warning information to provide a risk warning to the target object.

2. The method according to claim 1, characterized in that The determining, based on the evaluation label vector, a target crime type of the target object and at least one suspicious feature corresponding to the target crime type includes: Determining the target crime type of the target object according to the evaluation label vector; According to the target crime type, at least one attribute information and at least one financial data are determined in the feature information as the suspicious feature.

3. The method according to claim 1, characterized in that The feature extraction layer of the pre-trained risk assessment model extracts features from the attribute information and the financial data to obtain a fused feature vector corresponding to the attribute information and the financial data, including: Performing binning and discretization processing or equal-frequency binning and discretization processing on the attribute information and the financial data, respectively, to obtain a discrete vector of the attribute information and a discrete vector of the financial data; splicing the discrete vector of the attribute information and the discrete vector of the financial data to form a spliced ​​vector; The splicing vector is determined as a fusion feature vector corresponding to the attribute information and the financial data.

4. The method according to claim 2, characterized in that The determining the target crime type of the target object according to the evaluation label vector includes: Determine the crime type corresponding to the dimension of each component of the evaluation label vector; Determine the dimension where the maximum component in the evaluation label vector is located as the target dimension; The crime type corresponding to the target dimension is determined as the target crime type of the target object.

5. The method according to claim 2, characterized in that The step of determining, based on the target crime type, at least one attribute information and at least one financial data in the feature information as the suspicious feature includes: respectively determining the influence degree value between each piece of attribute information and each piece of financial data and the target crime type; sorting the attribute information and the financial data in descending order of the influence values ​​to form an information sequence including the attribute information and the financial data; selecting a previously preset amount of attribute information and financial data in the information sequence; The selected attribute information and financial data are determined as the suspicious features.

6. The method according to claim 2, characterized in that The step of determining, based on the target crime type, at least one attribute information and at least one financial data in the feature information as the suspicious feature includes: respectively determining the influence degree value between each piece of attribute information and each piece of financial data and the target crime type; The attribute information and financial data whose impact value is greater than a preset threshold are determined as the suspicious features.

7. The method according to claim 5 or 6, characterized in that The preset historical trial database stores: at least one crime type, at least one feature information corresponding to each crime type, and an IV value between each feature information and the crime type; The determining of the influence degree between each piece of attribute information and each piece of financial data and the target crime type includes: querying the IV value between each of the attribute information and each of the financial data and the target crime type from the historical trial database; The IV value between each piece of attribute information and each piece of financial data and the target crime type is determined as the influence degree value between the corresponding attribute information and the corresponding financial data and the target crime type.

8. The method according to claim 1, characterized in that The risk assessment model is trained by the following steps: inputting sample data of the sample subjects into the risk assessment model; Performing feature extraction on the sample data through the feature extraction layer of the risk assessment model to obtain a sample feature vector; Performing risk assessment on the sample feature vector through the risk assessment layer of the risk assessment model to obtain a sample assessment label vector of the sample object; Input the sample evaluation label vector into a preset loss model to obtain a loss result; According to the loss result, the parameters in the risk assessment model are updated using the stochastic gradient descent method until the sample evaluation label vector output by the updated risk assessment model meets the preset conditions, and then the training of the risk assessment model is stopped.

9. The method according to claim 8, characterized in that Inputting the sample evaluation label vector into a preset loss model to obtain a loss result includes: Obtaining a preset label corresponding to the sample data; Encode the preset label using a one-hot encoding rule to obtain an encoded label vector; Calculate the distance between the sample evaluation label vector and the encoding label vector using the loss function in the preset loss model; The loss result is determined according to the distance.

10. The method according to claim 8, characterized in that The method further comprises: After determining the target crime type of the target object and at least one suspicious feature corresponding to the target crime type, obtaining a review operation of a reviewer, wherein the review operation includes an evaluation operation for the target crime type and the suspicious feature; When the evaluation operation indicates that the prediction accuracy of the target crime type and the suspicious feature is greater than the accuracy threshold, the feature information of the target object is updated as the sample data into the sample database, and The target crime type is determined as a preset label corresponding to the sample data.

11. A risk warning device, characterized in that: include: an acquisition module, configured to acquire characteristic information of a target object, wherein the characteristic information includes at least attribute information of the target object and financial data corresponding to the financial business of the target object; a feature extraction module, configured to extract features from the attribute information and the financial data using a feature extraction layer of a pre-trained risk assessment model, and obtain a fused feature vector corresponding to the attribute information and the financial data; A risk assessment module, configured to perform risk assessment on the fused feature vector through the risk assessment layer of the risk assessment model to obtain an assessment label vector of the target object; a determination module, configured to determine, based on the evaluation label vector, a target crime type of the target object and at least one suspicious feature corresponding to the target crime type; The sending module is used to send at least one of the target crime type and the suspicious feature as risk warning information to the client to provide risk warning to the target object.

12. The device according to claim 11, characterized in that The risk assessment model at least has an input layer, the feature extraction layer, the risk assessment layer and an output layer.

13. The device according to claim 11, characterized in that The evaluation label vector is a label vector used to determine the target setting type of the target object. The evaluation label vector has at least two dimensions, and each dimension corresponds to a crime type.

14. The device according to claim 11, characterized in that The determining module is further configured to: The target crime type of the target object is determined according to the value of the component of each dimension in the evaluation label vector.

15. The device according to claim 14, characterized in that The determining module is further configured to: Determine the crime type corresponding to the dimension of each component of the evaluation label vector; Determine the dimension where the component with the maximum value in the evaluation label vector is located as the target dimension; The crime type corresponding to the target dimension is determined as the target crime type of the target object.

16. A risk warning device, characterized in that: include: a memory for storing executable instructions; A processor, configured to implement the risk warning method according to any one of claims 1 to 10 when executing the executable instructions stored in the memory.

17. A computer-readable storage medium, characterized in that Executable instructions are stored, which are used to cause a processor to execute the executable instructions to implement the risk warning method described in any one of claims 1 to 10.

18. A computer program product comprising computer instructions stored in a computer-readable storage medium; in, The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor is used to execute the computer instructions to implement the risk warning method described in any one of claims 1 to 10.

Citation Information

Patent Citations

  • Transaction data processing method and device, computer equipment and storage medium

    CN109784662A

  • Risk account identification method and device, electronic equipment and medium

    CN110852881A